U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-35842

Change History

New CVE Received by NIST 5/17/2024 11:15:21 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

ASoC: mediatek: sof-common: Add NULL check for normal_link string

It's not granted that all entries of struct sof_conn_stream declare
a `normal_link` (a non-SOF, direct link) string, and this is the case
for SoCs that support only SOF paths (hence do not support both direct
and SOF usecases).

For example, in the case of MT8188 there is no normal_link string in
any of the sof_conn_stream entries and there will be more drivers
doing that in the future.

To avoid possible NULL pointer KPs, add a NULL check for `normal_link`.
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/b1d3db6740d0997ffc6e5a0d96ef7cbd62b35fdd [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/cad471227a37c0c7c080bfc9ed01b53750e82afe [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/cde6ca5872bf67744dffa875a7cb521ab007b7ef [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/e3b3ec967a7d93b9010a5af9a2394c8b5c8f31ed [No types assigned]